Cloud Security Engineer

    Cloud Security Engineer – Azure | Entra ID | Policy as Code | Amsterdam [€120K + car]

    [Business Critical IT / Managed Services]

    The baseline is covered, nobody is getting breached today. I am looking for the engineer that is thinking about tomorrow: guardrails in code, supply chain and vulnerability scanning inside the pipelines, and an answer for agentic AI security.

    My client runs business critical infrastructure for large organisations, much of it in highly regulated sectors under DORA and NIS. Each client environment belongs to one dedicated team that designs it, builds it and then runs it for years, with the technical mandate inside that team rather than above it. Security touches it all. Not in a separate function checking other people’s work after the fact. As part of a team of senior engineers each with their own niche, on an environment that is close to greenfield and properly mission critical.

    What you’ll do

    Your job is the security of a live Azure platform, from the identity model down to the egress rules. Entra ID is where most of it starts, so Conditional Access, Privileged Identity Management, role based access control and identity governance, and you know why Entra is not simply a part of Azure. Guardrails go in as code through Terraform and Azure DevOps, so the insecure thing becomes hard to deploy rather than something you catch afterwards. Defender for Cloud covers posture, Sentinel covers detection and the KQL is yours to write and tune. Beyond that there is real room: supply chain security, vulnerability management, and securing how the teams build with AI agents are all areas waiting for someone with a view on them. Regulation is part of the furniture here, so you should know what DORA, NIS and ISO ask of you, but the auditing is somebody else’s job. Yours is making sure it is green when they arrive.

    Your profile

    •     6+ years in Azure infrastructure or cloud engineering, with security as your focus in recent years, so you can still build the platform you are securing

    •     Entra ID at depth: Conditional Access, Privileged Identity Management, role based access control, identity governance

    •     Sentinel and Defender for Cloud, with your own KQL rather than the built in rules

    •     Terraform and Azure DevOps pipelines, plus PowerShell, and ideally Ansible

    •     Supply chain security and vulnerability management, or a strong interest in taking that on

    •     Comfortable working inside regulated environments such as DORA, NIS and ISO

    •     Fluent English, Dutch is a plus

    What’s in it for you

    Up to €120K gross per year, a lease car, and a strong package on top of that. A permanent contract from day one. Three days a week in the Amsterdam office, the rest from wherever you work best. Budget for certification, training and conferences, and the room to actually use it.

    Interested?

    Contact me at s.vanderiet@doghouse.nl